QQ‑FIFA‑HNDL‑2026 / REV N PUBLIC / FOR RELEASE
Enterprise Quantum Risk Intelligence

Harvest Now, Decrypt Later: Football's Most Sensitive Data Is Living on a Quantum Clock

Cardiac, medical, and identity records from players across 211 nations, collected for life and protected by classical public-key cryptography with a published migration and deprecation horizon. We do not claim to know whether FIFA has a post-quantum plan. This report shows why the risk is material, time-sensitive, and impossible to remediate after the fact.

Issued
Public release 11 June 2026 · Classification PUBLIC · Analysis as of April 2026 · Appendix B search re-run on publication date
Report Type
Public-evidence structural risk analysis. Not a technical audit or internal system inspection.
Scope
FIFA global data infrastructure · 211 member associations · 6 confederations
Prepared By
Qtonic Quantum Research Team · Miami, FL
PUBLIC RESEARCH REPORT · FOR PUBLIC RELEASE. This is a structural risk analysis and a statement of opinion, not an allegation of fact. It does not allege that FIFA, any confederation, any member association, or any individual has experienced a data breach, or that any harvest-now-decrypt-later operation is targeting football data. Individuals named herein appear solely as publicly documented examples of athletes who later entered public life. This report makes no statement or implication that any named individual's data has been collected, intercepted, harvested, transmitted, or decrypted, or that any named individual faces any specific or actual risk. FIFA and all third-party names and marks belong to their respective owners. No affiliation or endorsement is implied. Full notices on the closing pages.
Public research report // Not a guarantee of results© 2026 Qtonic Quantum Corp
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCEQQ-FIFA-HNDL-2026
00
For the decision-maker

Executive Brief

Two minutes. The full analysis follows in Sections 1 through 12.

Qtonic Quantum HNDL Risk Rating: CRITICAL  C3

Primary driver: zero remediability of cardiac, medical, and identity data, including any biometric elements present, after future decryption. This is a qualitative rating derived from the five-variable HNDL framework in Section 10. It is not a numerical score and is not a prediction of any specific event.

The Problem

FIFA mandates lifetime-sensitive cardiac, medical, and identity-related data collection across its global competition and registration environment. Where biometric elements are present in identity records, the risk becomes more severe, because those elements cannot be rotated, reissued, or expired. This data is protected by classical public-key cryptography, which has a published migration path under NIST and government guidance even where private-sector timelines vary. The data's confidentiality horizon is measured in decades. The encryption's guarantee is not.

Why FIFA Specifically
  • Mandatory, no-opt-out collection across 211 member associations. We have not identified a comparable public case in sport combining mandatory medical screening, global identity registration, 211-member-association concentration, and long-term political sensitivity.
  • FIFA Connect concentrates identity and registration data across 211 member associations; medical data moves cross-border through documented workflows.
  • A documented pattern of footballers entering national political office, one at head-of-state level. Future political value is unknowable at collection time.
  • To our knowledge, and within the sources reviewed (search refreshed June 2026), no major football governing body has publicly announced a PQC migration program.
Timeline Pressure

The 2026 FIFA World Cup (US / Canada / Mexico, kickoff 11 June 2026) is likely to generate one of the most concentrated bursts of cross-border medical and registration-related data transfers. It begins with no announced PQC migration plan identified in reviewed sources.

Recommended First Step

A cryptographic inventory: a complete map of where cardiac, medical, and identity data is stored, how it is encrypted, and which algorithms are in use. This is the prerequisite for any migration program, and it can begin immediately.

The Asymmetry of Regret

Migrate and be wrong about the quantum timeline: stronger cryptography deployed, implementation cost incurred, no downside to data subjects. Do not migrate and be wrong: lifetime-sensitive data for players across 211 nations is permanently compromised, with no remediation possible after the fact. The question is whether migration completes before the data's confidentiality window closes.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCEQQ-FIFA-HNDL-2026
Navigation

Contents

Reading note

Every claim in this report is assigned to one of three evidence categories, marked inline where it matters. The integrity of the analysis depends on transparent sourcing and clearly bounded claims.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§01 · QQ-FIFA-HNDL-2026
01
Section One

Executive Summary

This report examines the structural harvest-now-decrypt-later (HNDL) risk facing FIFA's global data infrastructure. It is not an allegation of a specific breach or a specific intelligence operation. It is an analysis of whether the data FIFA collects, the encryption protecting it, and the routes it travels create a risk profile that warrants differentiated attention relative to other organizations facing the same general quantum cryptanalysis threat.

Four characteristics distinguish FIFA's data environment from most other organizations. First, mandatory cardiac and medical data collection with no opt-out, compulsory for all FIFA competitions since 2010. Second, concentration of identity and registration data from 211 member associations through FIFA Connect, with medical and PCMA data moving cross-border through documented workflows rather than a publicly documented central clinical repository. Third, the unpredictable future political significance of the data subjects, with documented cases of professional footballers later entering national political office, including one head-of-state case. Fourth, routine cross-border data transit as a standard operational requirement, across fiber-optic infrastructure publicly documented as subject to bulk signals-intelligence collection.

To our knowledge, no major football governing body has publicly announced a post-quantum cryptography migration program. NIST published the post-quantum standards (FIPS 203, 204, 205) in August 2024. The algorithms exist. Whether or not such a plan exists internally, the risk is material: lifetime-sensitive data, vulnerable public-key cryptography, and no way to remediate after the fact. That is the central finding of this report.

Mandatory Collection

Cardiac and medical data collection compulsory for all FIFA competitions since 2010. No opt-out. Non-adherence is a sanctionable offence.

211-Country Concentration

Identity and registration data from 211 member associations concentrates through FIFA Connect; medical data moves through documented cross-border workflows.

Political Significance

Documented cases of footballers entering national political office, including one head of state. Future political value is unknowable at collection time.

No Public PQC Plan

To our knowledge, and within the sources reviewed (refreshed June 2026), no major football governing body has publicly announced a PQC migration program.

Two research preprints published in March 2026 argue that the resource requirements for breaking elliptic-curve cryptography may be substantially lower than previously estimated. Multiple independent programs now describe plausible engineering paths to a cryptographically relevant quantum computer. The precise cost and timeline remain uncertain and are analyzed under three scenarios in Section 6. The thesis of this report does not depend on a specific cost figure or arrival date. It depends on whether such a machine becomes available within the decades-long confidentiality window of cardiac, medical, and identity data. Appendix G demonstrates that the thesis holds under timeline delays extending to 2060 and beyond.

The confidentiality horizon of cardiac ECG data, medical history, genetic predisposition markers, and passport-level identity data is measured in decades, not years. If any portion has been passively collected in transit and stored for future decryption, the exposure cannot be remediated after the fact. The report's recommended actions, beginning with a cryptographic inventory, are set out in Section 10.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCEFIG · QQ-FIFA-HNDL-2026
FIG
At a glance

The Risk in Four Views

Source-based visualizations of the report's core findings. Figures are qualitative and illustrative of the analysis in Sections 6, 9, and 10. They are not predictions and not numerical scores.

FIG.1   Resource Estimates by Problem Class
RSA-2048 factoring and ECC-256 discrete log, shown as separate series. Not directly comparable.
1B10M1M100k10k RSA-2048ECC-256 2012201920252026 ~1B (2012 estimate) ECC-256 ~26k
Logarithmic scale, 2012–2026, two problem classes on one scale, not directly comparable across classes. Filled circles, solid line: RSA-2048 (physical qubits). Open squares, dashed segment: ECC-256 (physical-qubit equivalent; the underlying logical-qubit count for ECC-256 is on the order of 1,200–1,450, with the remainder being fault-tolerance overhead). Sources: Gidney / Ekerå 2019; Gidney 2025 (arXiv:2505.15917); Google Research and Cain et al. (arXiv:2603.28627), March 2026 preprints pending peer review. Full table, caveats, and citations: §6.1.
FIG.2   Sensitivity vs Decryption Window
Data confidentiality horizon against the plausible arrival of cryptanalysis.
DATA SENSITIVITY Cardiac · genetic · identity · sensitive through ~2084+ CRYPTANALYSIS PLAUSIBLE 20302036+ EXPOSURE WINDOW → 2024204020602080
Harvested ciphertext stays exploitable until the data loses sensitivity. Capability plausibly arrives decades inside that window. SRC §6.4, App G.
FIG.3   HNDL Risk Profile
Each variable's contribution to overall risk (qualitative).
V VALUEHIGHS HORIZONLONGP(H) HARVESTMEDP(Q) Q-DECRYPTRISINGR REMEDIABILITYNONE
Five-variable framework, §10.4. Low remediability (R) is the dominant driver of the CRITICAL rating. Not a numerical score.
FIG.4   Public PQC Migration Posture
Public migration announcements by sector (qualitative).
US FEDERALFINANCIALCLOUD / TECHHEALTHCAREGLOBAL FOOTBALLNONE
Reviewed public sources, June 2026. Football: no public plan identified. SRC §9.3, App B.
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§02 · QQ-FIFA-HNDL-2026
02
Section Two

Evidence Boundaries & Methodology

This report distinguishes three categories of evidence throughout. Every claim is assigned to one of these categories, and the category is either stated explicitly or inferable from context. This discipline is intentional.

C1  Category 1 · Documented Facts

Claims sourced to peer-reviewed literature, official FIFA documentation, government publications, or primary reporting by established news organizations. Examples: FIFA's mandatory PCMA program (British Journal of Sports Medicine; PMC3596861, PMC4413678, PMC12171438); FIFA Connect (inside.fifa.com); Snowden disclosures (The Guardian, The Washington Post); NIST FIPS 203/204/205 (csrc.nist.gov); the public roles of Weah, Romário, and Shevchenko (Britannica, official government records).

C2  Category 2 · Reasonable Inferences

Claims based on the absence of contrary public evidence or standard industry practice. Examples: that encryption protecting FIFA data in transit uses classical public-key cryptography, and that no major football governing body has publicly announced PQC adoption. See Appendix B for the supporting search methodology.

C3  Category 3 · Structural Risk Analysis

Claims about what could happen given documented infrastructure, known SIGINT capabilities, and the quantum computing trajectory. The HNDL threat model is described by NIST, the Federal Reserve (September 2025), and multiple national cyber authorities. Application of this model to FIFA's specific data environment is the Qtonic Quantum Research Team's analysis. Where a claim falls in Category 2 or 3, bounded language is used: "to our knowledge," "no public evidence can rule out," "may become vulnerable under plausible assumptions."

2.1 Limitations of This Report

These limitations are inherent to the subject matter. They do not invalidate the thesis. They define its boundaries.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§03 · QQ-FIFA-HNDL-2026
03
Section Three

FIFA's Data Collection Infrastructure

FIFA operates one of the largest centralized sports-data infrastructures in the world. It spans 211 member associations across six confederations and serves as the authoritative system for player registration, international transfers, competition management, and medical compliance.

3.1 The Pre-Competition Medical Assessment C1

Following the death of Marc-Vivien Foé during the FIFA Confederations Cup in 2003, FIFA developed a standardized pre-competition medical assessment (PCMA) program. It was first implemented at the 2006 FIFA World Cup in Germany, introduced to women's and youth competitions in 2007 and 2010, and made compulsory for all FIFA competitions by the FIFA Executive Committee. The protocol includes a personal and family medical history questionnaire, a focused physical examination, a 12-lead resting electrocardiogram (ECG), and, when clinically indicated, transthoracic echocardiography, laboratory blood analysis, and exercise stress testing. Non-adherence is a sanctionable offence.

A 2024 global survey of 165 of 211 FIFA member associations found that 81% recommended or mandated cardiac screening. Among those, 92% used a protocol including at least medical history, physical examination, and 12-lead ECG for adult male players.

SRC: Junge et al., BJSM 2012 (PMC3596861) · Dvorak et al., BJSM 2015 (PMC4413678) · FIFA consensus statement, BJSM 2025 (PMC12171438)

3.2 FIFA Connect & the Global Registration System C1

FIFA Connect assigns a unique global FIFA ID to every registered player, coach, referee, and official, processing identity documentation across all 211 member associations. Integration was mandated by FIFA Circulars 1654 (Nov 2018) and 1679 (Jul 2019), with a July 2020 deadline. The platform includes the FIFA Connect ID Service, the Data eXchange Platform (DXP), and interfaces with the Transfer Matching System (TMS). When a player transfers internationally, TMS generates an Electronic Player Passport (EPP) compiling registration history from age 12. Medical disclosures are part of the transfer process.

SRC: inside.fifa.com/transfer-system/clearing-house · inside.fifa.com/advancing-football/fifa-connect · support.fifaconnect.org

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§03 · QQ-FIFA-HNDL-2026 · CONT.

3.3 Data Types Collected

Data TypeCollection MechanismSensitivity Horizon
12-lead resting ECGPCMA (mandatory)Lifetime
Personal / family medical historyPCMA questionnaireLifetime
Echocardiography resultsPCMA (when indicated)Lifetime
Laboratory blood analysisPCMA (when indicated)Years → lifetime
Passport / identity data (incl. any biometric elements present)FIFA Connect registrationLifetime
Transfer medical disclosuresTMS international transfersYears → lifetime
Registration history (age 12+)Electronic Player PassportLifetime

CRITICAL CHARACTERISTIC: much of this data, especially cardiac, medical-history, registration-history, and biometric elements where present, cannot be meaningfully rotated, reissued, or expired. A cardiac ECG from 2024 remains valid and sensitive in 2040, 2060, and beyond.

3.4 Cross-Border Data Transit Patterns

Transfer medical disclosures move between clubs in different countries. Tournament PCMA results flow from host-nation facilities to FIFA (Zurich) and confederation offices in Cairo, Kuala Lumpur, Miami, Luque, Auckland, and Nyon. Registration data is exchanged continuously across 211 member associations through FIFA Connect. Each flow crosses at least one national border, many crossing multiple borders through undersea fiber-optic infrastructure.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§04 · QQ-FIFA-HNDL-2026
04
Section Four

Why This Data Is Different

The HNDL threat applies to every organization using quantum-vulnerable cryptography. This section addresses whether FIFA's specific data environment warrants differentiated attention. The answer is yes. Not because any single factor is unique, but because of the combination.

4.1 Mandatory Collection, No Opt-Out

Players cannot refuse mandatory cardiac and medical assessment for covered competitions, and FIFA Connect processes identity-related records across the global registration environment. Where biometric elements are present, the irreversibility risk becomes more severe. The PCMA has been compulsory for all FIFA competitions since 2010, with non-adherence a sanctionable offence. Few health systems present the same combination of mandatory collection, global federation, athlete identity, and cross-border governance, and we are not aware of one that mandates cardiac screening across 211 countries with no right of refusal.

4.2 Unmatched Concentration Across Jurisdictions

FIFA Connect concentrates identity and registration data, including any biometric elements present, on players from virtually every nation. Medical and PCMA data move cross-border through documented workflows over the same monitored routes; public sources do not establish a single central clinical repository. The centralized design of FIFA Connect means interception at key transit hubs, particularly those serving FIFA headquarters in Zurich or major confederation offices, could expose identity and registration data from a disproportionately large number of member associations at once. That concentration ratio is difficult to match outside national passport systems.

4.3 Unpredictable Future Political Value

Footballers are collected as athletes. Some later become presidents, senators, and wartime political leaders (see Section 7). FIFA is one of the only organizations that compels lifetime-sensitive data collection from a large population whose future political significance is unknowable at the time of collection.

4.4 Routine Cross-Border Transit

FIFA's data crosses borders as standard operations, not as the exception. Those transit routes cross fiber-optic infrastructure publicly documented as subject to bulk signals-intelligence collection. The attack surface is the entire set of international data routes the sport requires to function, with no path to avoid it without ceasing operations.

4.5 Comparison to Other Sectors

FactorHospitalLaw FirmDefense ContractorFIFA
Collection voluntary?YesYesVariesNo (sanctionable)
Jurisdictional scope1 country1–31–5211 countries
Subjects become political?RarelySometimesSometimesDocumented pattern
Routine cross-border transit?RarelySometimesYes (classified)Yes (standard ops)
Data rotatable?NoNoNoNo
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§04 · QQ-FIFA-HNDL-2026 · CONT.

4.6 Comparable Organizations

International Olympic Committee. The IOC requires medical examinations but operates on a quadrennial cycle with roughly 10,500 athletes per event. It does not maintain a year-round centralized registration system comparable to FIFA Connect across 211 federations. The episodic nature of collection substantially reduces the attack surface relative to FIFA's continuous flows.

World Anti-Doping Agency. WADA's ADAMS system tracks athlete whereabouts and biological-passport data globally and is the closest analogue in reach. But its data is primarily biochemical rather than cardiac or identity-biometric, and sensitivity horizons are typically career-length, not lifetime.

National passport systems. The closest analogue in biometric sensitivity and mandatory participation. But they are operated by a single sovereign with dedicated security infrastructure and legal frameworks. FIFA operates a comparable footprint without sovereign-grade security, across 211 jurisdictions of widely varying cybersecurity maturity. The least-protected member association sets the ceiling for the whole network.

FIG.5   Time to Remediate After Compromise
How quickly a compromised credential or record can be replaced. Conceptual scale, qualitative.
Passwordminutes to hours · rotate Payment carddays · reissue TLS certificatedays to weeks · revoke and reissue Passport numbermonths to years · re-document Cardiac / medical recordNEVER · CANNOT BE ROTATED, REISSUED, OR EXPIRED Identity-biometric elementsNEVER · PERMANENT FOR THE LIFE OF THE SUBJECT
Remediability is the dominant variable in the HNDL framework (Fig.3). A compromised password is rotated and a compromised card is reissued. A decrypted cardiac record, and any biometric elements present in an identity record, cannot be remediated by any future action. Qualitative comparison. C3
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§05 · QQ-FIFA-HNDL-2026
05
Section Five

The Harvest-Now-Decrypt-Later Threat Model

HNDL requires three conditions to be simultaneously true. First, the ability to passively collect encrypted traffic in transit. Second, the ability to store that traffic indefinitely at low cost. Third, a reasonable expectation that the encryption will become breakable within the useful lifetime of the data. For lifetime-sensitive data, even a distant quantum timeline creates present-day exposure. The harvest happens now. The decryption happens later. The victim never knows.

01 · Passive Collection

A fiber tap captures encrypted traffic silently, without altering the signal.

02 · Indefinite Storage

Cold storage at roughly $0.01–0.02 per GB per month. The marginal cost of retention is negligible.

03 · Future Decryption

A cryptographically relevant quantum computer running Shor's algorithm breaks the recorded key exchange.

5.1 How Easy Is the Harvest C1

As much as 99% of intercontinental internet traffic travels through undersea fiber-optic cables. At landing points and amplification stations (roughly every 80 km for undersea cables), data can be copied without interrupting flow. Documents disclosed by Edward Snowden in 2013 revealed GCHQ's Tempora program collected approximately 21 million gigabytes per day from fiber-optic cables. INCENSER pulled approximately 14 billion pieces of internet data per month from a single submarine cable. Equipment for fiber-optic interception is commercially available at relatively low cost.

What the harvest requires / costs / why it is undetectable

Requires: access to fiber infrastructure at a landing point, amplification station, or cooperating telco. No breach of FIFA systems, no malware, no insider.  Costs: for a nation-state with existing SIGINT infrastructure, effectively nothing beyond marginal cold storage.  Undetectable: passive tapping does not alter the signal. No alarm fires. No log entry is created. The target has no forensic visibility.

5.2 Documented Bulk Collection Programs C1

ProgramOperatorMethodScale
TemporaGCHQ (UK)Fiber tapping via cooperating telcos~21M GB/day
INCENSERNSA / GCHQSingle submarine cable (Asia–Europe)~14B pieces/mo
UpstreamNSA (US)Fiber infrastructure on US soilClassified
USS Jimmy CarterUS Navy / NSAPhysical submarine cable tappingClassified

SRC: The Guardian (Tempora, Jun 2013) · Channel 4 News / Süddeutsche Zeitung (INCENSER, Nov 2014) · Privacy International · AP (USS Jimmy Carter, 2005) · Wilson Center (Optical Core Infrastructure, Feb 2024)

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§05 · QQ-FIFA-HNDL-2026 · CONT.

5.3 Technical Analysis: Encryption in Transit C2

FIFA has not publicly disclosed its encryption configuration. Based on standard industry practice, web-based data exchanges are likely protected by TLS 1.2 or 1.3 with classical key exchange (ECDHE-RSA or X25519). Both are quantum-vulnerable. TLS 1.3 provides forward secrecy against classical key compromise but does not protect against quantum cryptanalysis of a recorded session. HNDL captures the entire session including the ephemeral key exchange, which becomes breakable under Shor's algorithm. Hybrid post-quantum key agreement is already deployed or tested in major production environments, including Chrome and Cloudflare. Signal has separately deployed post-quantum protections in its messaging protocol. The technology to protect data flows of this kind exists today. To our knowledge, and within the sources reviewed, no football governing body has publicly announced deploying it.

5.4 Historical Precedents

East German Stasi files. Medical and personal data collected over four decades was weaponized for coercion after reunification. Data collected under one arrangement can be weaponized under a different one.  OPM breach (2015). Security-clearance files of 21.5 million people, including decades-old medical information, were exposed. Centralized identity data retains intelligence value indefinitely.  Equifax breach (2017). PII of 147 million individuals exposed. Unlike passwords, SSNs and biometrics cannot be rotated. The exposure is permanent.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§06 · QQ-FIFA-HNDL-2026
06
Section Six

The Quantum Cryptanalysis Timeline

ROLE IN THESIS: the central argument does not depend on a specific quantum timeline or machine cost. It depends on whether a cryptographically relevant quantum computer becomes available within the decades-long sensitivity horizon of the data FIFA collects. Cost estimates below are illustrative, not load-bearing.

6.1 Resource Estimates by Problem Class

YearTargetPhysical QubitsSource
2012RSA-2048~1 billionVan Meter et al.
2019RSA-2048~20 millionGidney / Ekerå (Google), peer-reviewed
2025RSA-2048~1 millionGidney (Google, updated)
31 Mar 2026ECC-256<500,000Google Research team preprint
30 Mar 2026ECC-256~26,000Cain et al. (Oratomic / Caltech / Berkeley) preprint

The two March 2026 preprints report physical-qubit figures that appear to conflict: the Google Research team estimates fewer than 500,000 physical qubits for ECC-256, while Cain et al. estimate roughly 26,000 for the same elliptic-curve problem (their headline figure, as few as 10,000 reconfigurable atomic qubits, applies to factoring). The gap is not an error in either paper. It reflects different error-correction assumptions: conservative overhead ratios in the Google work, high-performing qLDPC codes on reconfigurable neutral-atom hardware in Cain et al. Both agree on the direction: requirements are substantially lower than prior estimates. This report treats both as lower-bound illustrations of a compressing requirement, not engineering specifications. The structural thesis rests on the peer-reviewed 2019 baseline and the data's sensitivity horizon (Appendix G), not on either preprint.

PHYSICAL VS LOGICAL: the counts above are physical qubits. For ECC-256 the logical-qubit requirement is on the order of 1,200–1,450; the remainder is fault-tolerance overhead. Scott Aaronson, a noted skeptic of quantum-computing hype, called the Cain et al. result the more substantive of the two papers while cautioning that neither demonstrates a new experimental capability. This report adopts that caution: these are theoretical estimates, not demonstrated hardware.

6.2 Illustrative Cost Scenarios C3

Optimistic
~$10–20M
2029–2030
qLDPC near theoretical ratios, 99.9%+ gate fidelity. Fastest convergence of engineering gaps.
Base Case
~$15–30M
2030–2032
Moderate overhead ratios, 99.8–99.9% fidelity. Standard engineering progression.
Pessimistic
~$30–60M+
2033–2036+
qLDPC underperforms at 3–5× overhead. Fidelity stalls. Classical control lags.

ORDER-OF-MAGNITUDE ONLY. Derived from preprint inputs not yet peer-reviewed. Not engineering quotes. The thesis holds whether the machine costs $20M or $200M, provided it arrives within the data's sensitivity horizon.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§06 · QQ-FIFA-HNDL-2026 · CONT.

6.3 Engineering Gaps & Falsifiability

This thesis would be significantly weakened if any of the following were demonstrated. First, a publicly announced and documented PQC migration program at FIFA or a major confederation, already underway with verifiable deployment evidence. Second, FIFA transit architecture using end-to-end post-quantum encryption or avoiding monitored fiber entirely. Third, PCMA data remaining entirely within host-country systems, never transmitted cross-border. Fourth, a quantum cryptanalysis timeline extending beyond 2045, shrinking the overlap with the data's sensitivity horizon to a negligible range. Each condition is specific, verifiable, and testable. We are not aware of evidence supporting any of them as of April 2026.

6.4 Timeline Resilience

The critical question is not when a quantum computer will be built. It is whether one will be built within the sensitivity horizon of the data. A player screened at age 22 in 2024 will be 58 in 2060.

Quantum TimelinePlayer Age at DecryptionData Still Sensitive?Thesis Holds?
2030 · optimistic28Yes (cardiac, medical, identity)Yes
2035 · base case33YesYes
2040 · pessimistic38YesYes
2045 · very pessimistic43YesYes
2050 · extreme delay48YesYes
2060 · far horizon58Yes (cardiac, genetic, identity)Yes

Full resilience analysis in Appendix G. Under every scenario examined, including a 36-year delay, the data remains sensitive at the time of potential decryption.

6.5 Independent Expert Consensus C1

The report's thesis does not rest on the company's own view of the timeline. The Global Risk Institute, with evolutionQ, has surveyed quantum-computing experts annually since 2019. Its seventh edition (dated 9 March 2026, authored by Michele Mosca and Marco Piani, 26 respondents) reports that a cryptographically relevant quantum computer is considered quite possible within ten years and likely within fifteen, the highest ten-year estimate in the survey's history. At the twenty-year mark, a large majority of respondents place the probability at fifty percent or higher. That survey frames the decision through the Mosca Inequality: if the sensitivity life of the data plus the migration time exceeds the time to a quantum threat, the data is already at risk. For cardiac, genetic, and identity records with lifetime sensitivity, that inequality is satisfied under essentially every published estimate.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§07 · QQ-FIFA-HNDL-2026
07
Section Seven

The Political Exposure Dimension

Intelligence services have operational incentives to collect broadly and sort later. No analyst in 2006 could predict which players being screened at a FIFA World Cup would hold national office by 2018. The documented pattern of footballers entering political life, including at head-of-state level, establishes that FIFA's data subjects carry an unpredictable future political significance that compounds the HNDL risk in ways that are unusual relative to most hospital or corporate data environments.

7.1 Footballers Who Entered National Political Office C1

George Weah · Liberia. Professional career 1985–2003 at top European clubs. FIFA World Player of the Year 1995. Elected 25th President of Liberia in 2017. Served 2018–2024.

Romário · Brazil. Professional career 1985–2007. 1994 World Cup Golden Ball. Elected to the Brazilian Chamber of Deputies in 2010. Elevated to the Federal Senate in 2014, where he currently serves.

SRC: Britannica · official Liberian government biography (emansion.gov.lr) · FIFA.com official profiles · Brazilian Federal Senate public records

7.2 Athletes Who Entered Politics, Public Office, or National Sports Governance

NameSportCountryPolitical Role
George WeahFootballLiberiaPresident (2018–2024)
RomárioFootballBrazilFederal Senator (2014–)
Andriy ShevchenkoFootballUkrainePresident, Ukrainian FA (2024)
Imran KhanCricketPakistanPrime Minister (2018–2022)
Manny PacquiaoBoxingPhilippinesSenator (2016–2022)
Vitali KlitschkoBoxingUkraineMayor of Kyiv (2014–)
Hakan ŞükürFootballTurkeyMember of Parliament (2011–2015)
PeléFootballBrazilMinister of Sport (1995–1998)

7.3 The Coercion Risk Model C3

The coercion risk is structural, not an allegation about any named individual. Data treated as routine health information at collection can become leverage against someone later operating in public life. No intelligence service can predict which current player will matter politically in 2045.

FIG.6   The Collection-to-Office Gap
PLAYING CAREER · DATA COLLECTED GAP · 10–15+ YEARS NATIONAL OFFICE DATA SENSITIVITY HORIZON · LIFETIME · ENCRYPTION HARVESTED IN YEAR 0 IS STILL EXPLOITABLE HERE CAREER YEAR 0+20 YEARS+40 YEARS
Documented pattern shown generically: in the 7.1 case, election to head of state came 14 years after retirement. Harvested ciphertext from year 0 remains exploitable throughout. No statement is made about any individual's data. C3
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§08 · QQ-FIFA-HNDL-2026
08
Section Eight

Identity Fraud Beyond Sport

C3  Structural Risk Analysis

The claims in this section are structural inferences about what decrypted data could enable, not documented incidents. No specific incident of this nature has been documented.

FIFA Connect processes passport-level identity documentation across 211 member associations. Depending on the specific biometric data elements present in a registration record, a decrypted passport-level identity record from FIFA Connect, including any biometric elements present in that record, would, structurally, present exploitation vectors similar to identity documents obtained from government databases.

Document Forgery C3

Biometric elements from FIFA Connect records would structurally enable fraudulent identity documents across 211 jurisdictions of varying security control.

Impersonation C3

Passport-level identity data in decrypted form would structurally enable impersonation or synthetic-identity creation at a scale comparable to national identity databases.

Permanent Exposure

Unlike a password or access credential, a compromised biometric cannot be reissued, rotated, or expired. The exposure is permanent and irremediable.

A state or non-state actor with access to decrypted FIFA Connect records would, structurally, possess a database of passport-grade identity records spanning 211 nations: a resource with intelligence, criminal, and geopolitical applications well beyond the domain of sport. The permanence of biometric data makes this the highest-irreversibility risk in the entire threat model. This section analyzes the structural properties of the data, not alleged events.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§09 · QQ-FIFA-HNDL-2026
09
Section Nine

The Encryption Posture of Global Football

9.1 Absence of Public PQC Announcements C2

To our knowledge, as of 11 June 2026 and within the search scope described in Appendix B (refreshed on the publication date), no major football governing body has publicly announced a post-quantum cryptography migration program. This includes FIFA, all six confederations (AFC, CAF, CONCACAF, CONMEBOL, OFC, UEFA), and major domestic leagues. The absence is consistent across all tiers of the global football governance structure.

9.2 NIST Deprecation Timeline C1

9.3 Migration Progress by Sector

SectorPQC Status (Public)
US Federal GovernmentMandated. Inventory phase underway. CNSA 2.0 deadlines from 2027.
Financial ServicesActive pilots. SWIFT and major banks formally assessing migration.
Cloud / Big TechGoogle (2029 internal deadline), Apple (iMessage PQ3), Signal (PQXDH deployed).
HealthcareEarly awareness. Limited public announcements.
Global FootballNo public announcements to our knowledge. No migration timeline. No public inventory commitment.
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§09 · QQ-FIFA-HNDL-2026 · CONT.

9.4 Migration Complexity for Federated Governance

Timeline estimate. 3–5 years from committed decision to full deployment across all member associations. If started in 2026, completion lands 2029–2031, aligned with the NIST draft deprecation window. Deferred to 2028, completion lands 2031–2033, overlapping the quantum timeline under base and optimistic scenarios. Every year of delay narrows the safe migration window.

9.5 Data Protection & Regulatory Exposure

GDPR. EU player data is subject to Article 32 (appropriate technical measures), Article 9 (special categories including health data), and Article 25 (data protection by design). Known cryptographic deprecation may trigger a duty to assess quantum risk.  Swiss nFADP (2023). Requires appropriate technical measures for sensitive personal data; FIFA is directly subject.  Player data rights. Rights to information (Art. 13/14), access (Art. 15), and erasure (Art. 17). The compulsory, no-opt-out nature of the PCMA substantially increases regulatory sensitivity.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§10 · QQ-FIFA-HNDL-2026
10
Section Ten

What FIFA Would Need to Do

A post-quantum migration is a multi-year engineering and governance initiative, not a software patch. For an organization with FIFA's jurisdictional complexity, it requires sustained executive commitment, dedicated resources, and a structured framework. The technology exists today. What is required is the decision to begin.

  1. Cryptographic InventoryMap where cardiac, medical, and identity data is stored, how it is encrypted at rest and in transit, which algorithms are in use (RSA, ECDH, ECDSA, TLS versions), and which systems are migration-agile. This Cryptographic Bill of Materials (CBOM) is the prerequisite for everything that follows. Without it, migration cannot be scoped or sequenced.
  2. Network VisibilityCryptographic posture cannot be assessed at headquarters alone. Visibility into the posture of 211 member associations, six confederations, and major club systems is essential, because a compromise at any node can expose linked records or flows, depending on segmentation and access controls. The US federal CBOM program offers a working template for large distributed organizations.
  3. Migration TimelineNIST standards are finalized. Enterprise PQC migration requires 2–5 years. Begun in 2026, completion aligns with the draft 2030 NIST deprecation target. Deferred to 2028+, the window narrows and may overlap the quantum timeline under optimistic and base-case scenarios. The 2026 FIFA World Cup is a near-term forcing function for concentration of cross-border medical data.
  4. Risk Quantification FrameworkHNDL risk is a function of five variables: V (value of decrypted data), S (sensitivity horizon), P(H) (probability of harvest), P(Q) (probability of quantum decryption within S), and R (remediability). FIFA's cardiac, medical, and identity data scores high V, long S, non-trivial P(H), increasing P(Q), and zero R. These data types warrant highest prioritization within any migration sequencing.
  5. Cyber Insurance & Financial Risk Transfer C3Cyber insurers are tightening underwriting around systemic and catastrophic risk. The market has already moved to exclude state-backed and war-related cyber losses, and reinsurers are actively reframing how large, correlated cyber events are defined and priced. Harvest-now-decrypt-later sits squarely in that systemic-risk category: a single cryptanalytic advance could expose many insureds at once. It is reasonable to expect quantum readiness to enter underwriting questionnaires and pricing as that category matures. For a CFO, this is a plausible near-term financial trigger that does not depend on the quantum timeline being resolved, only on insurers treating quantum exposure as material.
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§11 · QQ-FIFA-HNDL-2026
11
Section Eleven

The Honest Counter

The Strongest Objection

Everything in this report is also true, in general terms, for hospitals, banks, law firms, and defense contractors. FIFA is not uniquely vulnerable. It is one node in a global system failing to prepare for quantum cryptanalysis. Given finite resources, should FIFA prioritize ahead of healthcare or national defense? That is a legitimate resource-allocation question.

Why the Counter Does Not Hold

The proportionality objection concedes the risk exists and disputes only the priority ranking. This report demonstrates the risk is material. The combination of four characteristics, mandatory no-opt-out collection, 211-country concentration, a documented pattern of subjects entering political life, including at head-of-state level, and routine cross-border transit across documented SIGINT infrastructure, distinguishes FIFA from any single-sector comparator. No single factor is unique. The combination is.


Cost of Acting and Being Wrong

The organization deploys stronger cryptography than it turns out to need. Implementation cost is incurred. There is no downside to data subjects. Cryptographic posture improves regardless of the quantum timeline.

Cost of Not Acting and Being Wrong

Lifetime-sensitive medical and identity data for players across 211 nations becomes permanently compromised, with no remediation possible. Cardiac ECGs, genetic markers, and biometric elements, where present, cannot be reissued. Political coercion risk materializes for former players in public life. Regulatory exposure under GDPR and nFADP activates.

The asymmetry of regret

The cost of migrating and being wrong is manageable. The cost of not migrating and being wrong is catastrophic and permanent. That asymmetry does not depend on a specific quantum timeline. It depends only on the data being sensitive for longer than the encryption is guaranteed to hold.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // ENTERPRISE QUANTUM RISK INTELLIGENCE§12 · QQ-FIFA-HNDL-2026
12
Section Twelve

Conclusions

01FIFA mandates collection of lifetime-sensitive cardiac, medical, and identity-related data from players across 211 nations through documented programs.C1
02That data crosses borders routinely through fiber-optic infrastructure documented as subject to bulk SIGINT collection.C1 C2
03To our knowledge, no major football governing body has publicly announced PQC migration. None identified in the sources reviewed (search refreshed June 2026).C2
04The highest-risk elements cannot be meaningfully rotated or expired. The sensitivity horizon is measured in decades.C3
05Resource requirements for quantum cryptanalysis are compressing across multiple independent programs. The thesis does not depend on any specific estimate, only on whether the machine arrives within the data's sensitivity horizon.C1 C3
06Professional footballers have entered national political office, including one documented head-of-state case.C1
One of the most sensitive data environments in professional sports is protected by cryptography with a published deprecation timeline. The data behind it lasts a lifetime. To our knowledge, and within the sources reviewed, no public plan for what comes next has been identified in football.
FIG.7   Migration Runway vs Deprecation Horizon
NIST IR 8547 (DRAFT) DEPRECATION TARGET · 2030 Begin 2026INVENTORY → RISK SCORING → PRIORITIZATION → HYBRID DEPLOYMENT → VALIDATION Begin 2028OVERRUNS TARGET · THREAT WINDOW 2026202820302032
Enterprise PQC migration historically requires 2–5 years (Section 10). Begun in 2026, a five-phase program completes near the draft 2030 federal deprecation target. Deferred to 2028, the same program overruns the target and overlaps the optimistic-to-base-case cryptanalysis scenarios in Section 6.2. Illustrative timeline. C3
Recommended Next Step

The recommended first action is a cryptographic inventory: a complete map of where cardiac, medical, and identity data is stored, how it is encrypted, and which algorithms are in use. It is not a speculative exercise. It is the prerequisite for any migration program and can begin immediately. The Qtonic Quantum Research Team is available to brief FIFA security leadership, designated counsel, or other qualified institutional stakeholders on cryptographic-inventory methodology for federated, cross-border data environments.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // APPENDICESAPX-A · QQ-FIFA-HNDL-2026
A
Appendix A

Source Documentation & Evidence Index

[1] Junge et al. "Feasibility of precompetition medical assessment at FIFA World Cups." BJSM 2012. PMC3596861.
[2] Dvorak et al. "F-MARC: promoting prevention of sudden cardiac arrest in football." BJSM 2015. PMC4413678.
[3] Baggish, Papadakis et al. "Recommendations for cardiac screening and emergency action planning in youth football: a FIFA consensus statement." BJSM 2025. PMC12171438.
[4] FIFA global cardiac screening survey, conducted Feb–Jul 2024, 165/211 MAs responding (78%); 81% of respondents recommend or mandate screening. Published BJSM 2025 (doi:10.1136/bjsports-2025-109751).
[5] FIFA. inside.fifa.com/advancing-football/fifa-connect/programme-details.
[6] FIFA. inside.fifa.com/transfer-system/clearing-house/systems-integration.
[7] FIFA. support.fifaconnect.org (FIFA Connect ID overview, registration guides).
[8] FIFA Circulars 1654 (Nov 2018) and 1679 (Jul 2019). Integration deadline Jul 2020.
[9] Snowden / Tempora: The Guardian, 21 Jun 2013. "GCHQ taps fibre-optic cables."
[10] INCENSER: Channel 4 News / Süddeutsche Zeitung (Nov 2014), reported within the broader WINDSTOP collection (The Washington Post, 2013); Privacy International (2013).
[11] USS Jimmy Carter: Associated Press, February 2005.
[12] Wilson Center. "Optical Core Infrastructure." February 2024.
[13] Privacy International. "GCHQ Tapping International Fibre-Optic Cables." 2013.
[14] Google Research team. ECC-256 resource estimate (<500,000 physical qubits). 31 Mar 2026. [Preprint, not peer-reviewed]
[15] Cain et al. "Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits." arXiv:2603.28627. 30 Mar 2026. [Preprint, not peer-reviewed]
[16] NIST. FIPS 203 (ML-KEM), 204 (ML-DSA), 205 (SLH-DSA). August 2024. csrc.nist.gov.
[17] NIST IR 8547, initial public draft (Nov 2024). Transition to Post-Quantum Cryptography Standards. Draft targets: deprecation 2030, disallowance 2035.
[18] George Weah: Britannica; official Liberian government biography (emansion.gov.lr); Al Jazeera; France24.
[19] Romário: FIFA.com official player profile; Brazilian Federal Senate public records.
[20] Shevchenko: UEFA.com official profile; Ukrainian Association of Football announcement, 2024.
[21] Qtonic Quantum cost analysis. Internal. Based on published component pricing. March 2026.
[22] Federal Reserve. Harvest-now-decrypt-later risk paper. September 2025.
[23] Mosca & Piani. "Quantum Threat Timeline Report 2025." Global Risk Institute / evolutionQ, 9 Mar 2026 (seventh edition, 26 expert respondents).
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // APPENDICESAPX-B · QQ-FIFA-HNDL-2026
B
Appendix B

Methodology: 'No Public Plan' Claims

The claim that no major football governing body has publicly announced PQC migration is based on the following bounded search methodology, disclosed in full to support informed interpretation of the claim's scope.

Search Scope

FIFA, all six confederations (AFC, CAF, CONCACAF, CONMEBOL, OFC, UEFA), the top five domestic leagues by revenue (Premier League, La Liga, Bundesliga, Serie A, Ligue 1), and the top 20 clubs by revenue (Deloitte Football Money League 2025).

Search Method

Web searches conducted between 15 March and 5 April 2026 using Google, Bing, and direct searches of organizational websites. Terms included combinations of [organization name] + "post-quantum," "PQC," "quantum-safe," "quantum-resistant," "FIPS 203," "ML-KEM," "cryptographic migration."

Result

Zero public announcements of PQC migration programs were identified across any entity in scope. The search was refreshed on the publication date, 11 June 2026, and no contrary public announcement was identified. This supports the claim as stated, "to our knowledge, no major football governing body has publicly announced," but does not prove no internal activity exists.

Exclusions & Limitations

We did not search private or internal communications, non-public board minutes, vendor contracts, or classified government assessments. This methodology would not detect unpublished internal assessments, vendor-initiated upgrades that are not publicly announced, or migration activity within IT infrastructure providers serving football organizations. The claim is bounded accordingly: it establishes the public posture, not the internal reality.

Operational note for delivery

Because this is a public release, the central claim is the one most exposed to falsification by a subsequent public announcement. The scoped search was refreshed on the publication date. It should be re-run and timestamped again immediately before any further reissue or update.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // APPENDICESAPX-C · QQ-FIFA-HNDL-2026
C
Appendix C

Glossary

CBOM
Cryptographic Bill of Materials. Inventory of all cryptographic assets in an organization.
CNSA 2.0
NSA's updated algorithm guidance for National Security Systems.
ECC / ECDSA / ECDH
Elliptic Curve Cryptography and its signature/key-exchange variants. Vulnerable to Shor's algorithm.
ECG
Electrocardiogram. Recording of the heart's electrical activity. Collected under the mandatory PCMA.
EPP
Electronic Player Passport. FIFA document compiling registration history from age 12.
FIPS 203/204/205
NIST post-quantum standards: ML-KEM, ML-DSA, SLH-DSA.
HNDL
Harvest Now, Decrypt Later. Threat model for future quantum decryption of today's encrypted data.
ML-KEM
Module-Lattice Key Encapsulation Mechanism. NIST FIPS 203.
ML-DSA
Module-Lattice Digital Signature Algorithm. NIST FIPS 204.
NSM-10
White House directive requiring federal cryptographic inventory and PQC migration.
PCMA
Pre-Competition Medical Assessment. FIFA's mandatory medical screening protocol.
PQC
Post-Quantum Cryptography. Algorithms designed to resist attacks by quantum computers.
qLDPC
Quantum Low-Density Parity-Check codes. Error-correction codes with lower overhead requirements.
RSA
Rivest-Shamir-Adleman. Public-key cryptosystem vulnerable to Shor's algorithm.
Shor's Algorithm
Quantum algorithm (1994) capable of breaking RSA and ECC encryption at scale.
TMS
Transfer Matching System. FIFA's international player-transfer processing system.
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // APPENDICESAPX-D · QQ-FIFA-HNDL-2026
D
Appendix D

FIFA Data Flow Diagram

Conceptual. Each edge represents a cross-border data-transit event. The FIFA Connect hub processes identity and registration data continuously across all 211 member associations, the primary HNDL attack surface.

FIFA ZURICH HUB CLUB MEDICAL STAFF→ PCMA results TOURNAMENT FACILITY→ ECG, echo, blood work MEMBER ASSOCIATION↔ DXP / 211 MAs TMS · TRANSFERS→ EPP, medical disclosure CONFEDERATION HQ← aggregated data
FromToData TypeTrigger
Club Medical StaffMember AssociationPCMA resultsRegistration
Member AssociationFIFA (Zurich)PCMA compliance, registrationCompetition deadline
FIFA (Zurich)Confederation HQAggregated dataTournament admin
Releasing ClubTMS (FIFA)Transfer medical, historyIntl transfer
TMS (FIFA)Acquiring ClubEPP, medical disclosureTransfer completion
FIFA Connect211 MAsFIFA ID, status updatesContinuous
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // APPENDICESAPX-E · QQ-FIFA-HNDL-2026
E
Appendix E

2026 World Cup Host-Country Data Protection

The 2026 FIFA World Cup (US / Canada / Mexico, kickoff 11 June 2026) is likely to generate one of the most concentrated bursts of cross-border medical and registration-related data transfers. Tournament PCMA data for players representing 211 nations will transit between host-country facilities, FIFA headquarters in Zurich, and all six confederation offices, within a compressed timeframe, across three distinct legal jurisdictions.

JurisdictionPrimary LawHealth-Data ClassificationCross-Border Rules
United StatesHIPAA, state lawsHealth data. Potentially PHI depending on covered-entity / business-associate context. State privacy & biometric laws (e.g., BIPA, CCPA) may also applySectoral
CanadaPIPEDASensitive personal infoAdequacy-based
MexicoLFPDPPPSensitive (health, biometric)Consent-based
EU (origin)GDPRSpecial category (Art. 9)SCCs / BCRs
Switzerland (HQ)nFADP (2023)Sensitive personal dataAdequacy list
The 2026 inflection point

If PQC is implemented before the tournament, it protects one of the most concentrated bursts of cross-border medical and registration-related data in FIFA's annual calendar. If not, that data joins existing potentially harvestable traffic, and cannot be recalled, rotated, or expired after the fact.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // APPENDICESAPX-F · QQ-FIFA-HNDL-2026
F
Appendix F

Timeline of Key Events

DateEvent
1994Shor's algorithm published. Theoretical basis for quantum cryptanalysis of RSA and ECC.
2003Death of Marc-Vivien Foé during FIFA Confederations Cup. Catalyst for systematic cardiac screening.
2006First mandatory PCMA implemented at FIFA World Cup, Germany.
2010PCMA made compulsory for ALL FIFA competitions. Non-adherence becomes sanctionable.
2013Snowden disclosures reveal Tempora (~21M GB/day) and INCENSER (~14B pieces/mo).
Jul 2020FIFA Connect integration deadline for all 211 member associations.
Aug 2024NIST FIPS 203/204/205 published. PQC standards finalized.
Mar 2026Cain et al. / Oratomic (~26,000-qubit) and Google Research (<500,000-qubit) ECC-256 preprints. Physical-qubit estimates compress.
Jun 20262026 FIFA World Cup kickoff (US/CAN/MEX). Peak cross-border medical-data concentration.
Jan 2027CNSA 2.0: new NSS acquisitions must be PQC-compliant.
2029Google internal PQC migration deadline. Optimistic scenario for a CRQC.
2030 / 2035NIST IR 8547 (initial public draft) deprecation (2030) and full disallowance (2035) targets for RSA/ECDSA.
Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // APPENDICESAPX-G · QQ-FIFA-HNDL-2026
G
Appendix G

Why the Thesis Holds If the Timeline Slips

A common objection to HNDL arguments is that the quantum timeline is uncertain and may extend well beyond current estimates. This appendix demonstrates that the thesis holds under substantially delayed timelines. The summary resilience table appears in Section 6.4; the full reasoning follows.

The Sensitivity Horizon Test

If a quantum computer capable of breaking classical encryption becomes available at any point before that data loses sensitivity, any encrypted copy collected in transit becomes decryptable. The thesis would be weakened only if (a) no such machine is built within the lifetime of the data subjects AND (b) no other cryptanalytic advance compromises the same algorithms during that period. Given the current trajectory across multiple independent programs, the likelihood of both holding for 50+ years appears low on present evidence, though it cannot be ruled out. This assessment may change as research evolves.

The Asymmetry of Regret

The cost of migrating now and being wrong is manageable: stronger cryptography deployed, implementation cost incurred, no downside to data subjects. The cost of not migrating and being wrong is potentially catastrophic: lifetime-sensitive data for players across 211 nations permanently compromised, with no remediation possible. For cardiac ECG data, genetic markers, and biometric elements where present, the balance of evidence suggests the data's sensitivity horizon will exceed the period during which current encryption can be considered reliable. The remaining uncertainty is not whether this gap exists, but how wide it will be.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QTONIC QUANTUM // LEGAL, NON-RELIANCE & PUBLIC RELEASE NOTICESQQ-FIFA-HNDL-2026
§
Back Matter

Legal, Non-Reliance & Public Release Notices

Disclaimer

This material is provided as a public research report for informational purposes only and does not constitute legal, regulatory, compliance, investment, security, or other professional advice. This report does not allege that FIFA, any confederation, any member association, or any individual has experienced a data breach, or that any specific harvest-now-decrypt-later operation is targeting football data. It describes a structural risk inherent in the use of quantum-vulnerable cryptography to protect lifetime-sensitive medical and identity data across a global data infrastructure. Cost estimates, timeline projections, and hardware assessments reflect Qtonic Quantum's analysis of publicly available research and are subject to meaningful uncertainty. The March 2026 papers referenced are preprints that had not completed peer review as of publication.

Non-Reliance

No person or entity should rely on the contents of this report as a basis for any decision or action without obtaining independent professional advice specific to their circumstances. Qtonic Quantum Corp expressly disclaims any and all liability for actions taken or not taken based on any or all of the contents of this report. This report is not an offer, solicitation, or recommendation to purchase any product or service. Qtonic Quantum Corp offers commercial services in the field this report addresses. Readers should weigh that interest.

Named Individuals

Individuals named in this report appear solely as publicly documented examples of athletes who later entered political or public life, drawn from public records and established reporting. This report makes no statement or implication that any named individual's data has been collected, intercepted, harvested, transmitted, stored, or decrypted, that any named individual's medical or biometric information is or was at risk, or that any named individual faces any specific or actual harm. References are illustrative of a general, documented pattern only. Their inclusion implies no criticism of any named individual. Biographical facts are drawn solely from public records.

Nature of Statements

Statements characterized as risk analysis, inference, projection, or structural assessment are expressions of opinion based on publicly available information, not assertions of fact. The evidence-category labels (C1 documented fact, C2 reasonable inference, C3 structural risk analysis) and the bounded language used throughout indicate the basis and confidence of each claim.

Public Release & Media Use

This report is approved for public distribution and may accompany press materials. Quotations attributed to the Qtonic Quantum Research Team or to Qtonic Quantum Corp in press materials are authorized only in the exact form approved in writing. Media inquiries may be directed to the contact details on the following page. Factual errors identified after publication will be corrected in subsequent versions and noted. Independent replication of the Appendix B search methodology is invited. Third-party names and marks, including FIFA, appear for identification and commentary only. Their use does not imply affiliation, sponsorship, or endorsement.

Copyright

© 2026 Qtonic Quantum Corp. All rights reserved. No part of this report may be reproduced, distributed, or transmitted in any form without the prior written permission of Qtonic Quantum Corp, except for brief quotations in critical reviews and noncommercial uses permitted by copyright law.

Public research report // Not a guarantee of resultsQQ-FIFA-HNDL-2026
QQ‑FIFA‑HNDL‑2026 / REV NEND OF DOCUMENT
Revision History

REV J–N (11 June 2026 release): corrected the INCENSER source citation (App A); separated RSA-2048 and ECC-256 resource estimates by problem class and added the logical-versus-physical qubit distinction (§6.1, FIG.1); softened the Google preprint attribution pending author confirmation; added §6.5 (Global Risk Institute expert survey); marked NIST IR 8547 as initial public draft at each mention; scoped concentration language to identity and registration data through FIFA Connect, with medical and PCMA data moving through documented cross-border workflows; updated the cardiac-survey citation to its 2025 BJSM publication; bounded the intercontinental-traffic figure; updated issue metadata and the contact block for the 11 June 2026 public release; corrected §7 framing to national political office with one documented head-of-state case and retitled the §7.2 table to include national sports governance; bounded the §10 network-exposure sentence to linked records and flows subject to segmentation and access controls; reworded the §2 example grouping to public roles; widened the closing briefing offer to qualified institutional stakeholders. No correction changes the report’s thesis or risk rating.

Qtonic Quantum
Contact
Qtonic Quantum Corp
Miami, FL
+1 (866) 4-QTONIC
info@qtonicquantum.com  ·  qtonicquantum.com
Public research report // Distributed with press materials // Not a guarantee of results  ·  © 2026 Qtonic Quantum Corp  ·  Post Quantum Ready